CVE-2018-7093: HP Integrated Lights-Out 3 Firmware

High severity, CVSS 8.6. EPSS: 3.5% chance of exploitation in the next 30 days.

A security vulnerability in HPE Integrated Lights-Out 3 prior to v1.90, iLO 4 prior to v2.60, iLO 5 prior to v1.30, Moonshot Chassis Manager firmware prior to v1.58, and Moonshot Component Pack prior to v2.55 could be remotely exploited to create a denial of service.

Affected products

  • HP Integrated Lights-Out 3 Firmware: before 1.90 (fixed in 1.90)
  • HP Integrated Lights-Out 4 Firmware: before 2.60 (fixed in 2.60)
  • HP Integrated Lights-Out 5 Firmware: before 1.30 (fixed in 1.30)
  • HP Moonshot Chassis Manager Firmware: before 1.58 (fixed in 1.58)
  • HP Moonshot Component Pack Firmware: before 2.55 (fixed in 2.55)

Published 2018-08-14. Last modified 2026-06-17.